CFTMON.EXE – Trojan Crypt

I recommend you UnHackMe - Ultimate Malware Killer for fast malware removal:

Free Download
Fully Functional 30-day Trial. No credit card is required.
Reviews
. EULA. Privacy Policy. Uninstall.

CFTMON.EXE – Trojan Crypt removal

FileMD5Virus Alias
CFTMON.EXE de40aa31317d94932ba9ce9b3bd9b3b9 Trojan Crypt
CFTMON.EXE de40aa31317d94932ba9ce9b3bd9b3b9 Trojan Eldorado
CFTMON.EXE de40aa31317d94932ba9ce9b3bd9b3b9 Trojan Downloader
CFTMON.EXE de40aa31317d94932ba9ce9b3bd9b3b9 Worm Autorun
CFTMON.EXE de40aa31317d94932ba9ce9b3bd9b3b9 Trojan Agent

CFTMON.EXE size: 267831 bytes
CFTMON.EXE hash: DE40AA31317D94932BA9CE9B3BD9B3B9

Created files:

%UserProfile%\cftmon.exe
%SysDir%\drivers\spools.exe

Autostart registry keys:

HKLM\Software\Microsoft\Windows\CurrentVersion\Run\ntuser: %WinDir%\System32\drivers\spools.exe
HKLM\Software\Microsoft\Windows\CurrentVersion\Run\autoload: %WinDir%\System32\config\Systemprofile\cftmon.exe
HKLM\System\CurrentControlSet\Services\Schedule\ImagePath: 43003A005C00570049004E0044004F00570053005C00730079007300740065006D00330032005C0064007200690076006500720073005C00730070006F006F006C0073002E006500780065000000
HKCU\Software\Microsoft\Windows\CurrentVersion\Run\ntuser: %WinDir%\System32\drivers\spools.exe
HKCU\Software\Microsoft\Windows\CurrentVersion\Run\autoload: %WinDir%\System32\config\Systemprofile\cftmon.exe

Detected by UnHackMe:

CFTMON.EXE
Default location: %USERPROFILE%\CFTMON.EXE

Dropper information:
MD5: b493e352b76e90ad60335267ea84354d
File size: 256417 bytes

Leave a Reply